CVE-2006-4339
published 2006-09-05CVE-2006-4339: OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
4.89%
91.1th percentile
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| debian | openssl | < openssl 0.9.8b-3 (bookworm) | openssl 0.9.8b-3 (bookworm) |
| debian | thunderbird | < firefox 1.5.dfsg+1.5.0.7-1 (sid) | firefox 1.5.dfsg+1.5.0.7-1 (sid) |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
| gnu | gnutls | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_cisco7.8HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
vendor_vmware·2008-03-17·CVSS 6.9
CVE-2006-2937 [MEDIUM] Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
VMSA-2008-0005: Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line
a. Host to guest shared folder (HGFS) traversal vulnerability On Windows hosts, if you have configured a VMware host to guest shared folder (HGFS), it is possible for a program running in the guest to gain access to the host's file system and create or modify executable files in sensitive locations. NOTE: VMware Server is not affected because it doesn't use host to guest shared folders. No versions of ESX Server, including ESX Server 3i, are affected by this vulnerability. Because ESX Server is based on a bare-metal hypervisor architecture and not a hosted architecture, and it doesn't include any shared folder abilities. Fusion and Linux based hosted product
Cisco
Multiple Vulnerabilities in OpenSSL Library
vendor_cisco·2006-11-08·CVSS 7.8
CVE-2006-4339 [HIGH] Multiple Vulnerabilities in OpenSSL Library
Multiple Vulnerabilities in OpenSSL Library
This is the Cisco PSIRT response to the multiple security advisories published by The OpenSSL Project. The vulnerabilities are as follows:
RSA Signature Forgery (CVE-2006-4339), described in http://www.openssl.org/news/secadv_20060905.txt
ASN.1 Denial of Service Attacks (CVE-2006-2937, CVE-2006-2940), described in http://www.openssl.org/news/secadv_20060928.txt
SSL_get_shared_ciphers() buffer overflow (CVE-2006-3738), also in http://www.openssl.org/news/secadv_20060928.txt
SSLv2 Client Crash (CVE-2006-4343), also in http://www.openssl.org/news/secadv_20060928.txt
As of this publication, there are no workarounds available for any of these vulnerabilities, but it may be possible to mitigate some of the exposure. This Security Response lists the
Red Hat
security flaw
vendor_redhat·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] security flaw
security flaw
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Red Hat
security flaw
vendor_redhat·2006-09-08·CVSS 4.3
CVE-2006-4790 [MEDIUM] security flaw
security flaw
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
BSD
FreeBSD-SA-06:19.openssl: Incorrect PKCS#1 v1.5 padding validation in crypto(3)
bsd_advisories·2006-09-06·CVSS 4.3
CVE-2006-4339 [MEDIUM] FreeBSD-SA-06:19.openssl: Incorrect PKCS#1 v1.5 padding validation in crypto(3)
FreeBSD-SA-06:19.openssl Security Advisory
The FreeBSD Project
Topic: Incorrect PKCS#1 v1.5 padding validation in crypto(3)
Category: contrib
Module: openssl
Announced: 2006-09-06
Affects: All FreeBSD releases.
Corrected: 2006-09-06 21:18:26 UTC (RELENG_6, 6.1-STABLE)
2006-09-06 21:19:21 UTC (RELENG_6_1, 6.1-RELEASE-p6)
2006-09-06 21:20:08 UTC (RELENG_6_0, 6.0-RELEASE-p11)
2006-09-06 21:20:54 UTC (RELENG_5, 5.5-STABLE)
2006-09-06 21:21:50 UTC (RELENG_5_5, 5.5-RELEASE-p4)
2006-09-06 21:22:39 UTC (RELENG_5_4, 5.4-RELEASE-p18)
2006-09-06 21:23:16 UTC (RELENG_5_3, 5.3-RELEASE-p33)
2006-09-06 21:24:04 UTC (RELENG_4, 4.11-STABLE)
2006-09-06 21:24:54 UTC (RELENG_4_11, 4.11-RELEASE-p21)
CVE Name: CVE-2006-4339
For general information regarding FreeBSD Security Advisories,
including descriptions
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2006-09-05
CVE-2006-4339 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL vulnerability
Philip Mackenzie, Marius Schilder, Jason Waddle and Ben Laurie of
Google Security discovered that the OpenSSL library did not
sufficiently check the padding of PKCS #1 v1.5 signatures if the
exponent of the public key is 3 (which is widely used for CAs). This
could be exploited to forge signatures without the need of the secret
key.
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Cisco
OpenSSL RSA Signature Forgery Vulnerability
vendor_cisco·2006-09-05·CVSS 5.0
CVE-2007-5810 [MEDIUM] OpenSSL RSA Signature Forgery Vulnerability
OpenSSL RSA Signature Forgery Vulnerability
OpenSSL versions 0.9.7j and prior and 0.9.8b and prior contain a vulnerability that could allow an unauthenticated, remote attacker to successfully pass a forged X.509 certificate.
The vulnerability could allow an unauthenticated, remote attacker to pass a forged Public-Key Cryptography Standards (PKCS)#1 Version 1.5 signature when signed by a certain type of RSA key. An attacker could exploit the vulnerability to access certificate-protected resources.
OpenSSL confirmed the vulnerability in a security advisory and released updated versions.
This vulnerability affects PKCS #1 v1.5 signatures if the exponent of the public key is 3, which is widely used by Certificate Authorities. An attacker will likely exploit this vulnerability to forge signa
Red Hat
CVE-2006-4339: OpenSSL before 0
vendor_redhat·2006-09-05·CVSS 4.3
CVE-2006-4339 [MEDIUM] CWE-347 CVE-2006-4339: OpenSSL before 0
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
A flaw was found in OpenSSL. When configured to use an RSA key with exponent 3, OpenSSL improperly removes PKCS-1 padding before generating a hash. This allows remote attackers to forge PKCS #1 v1.5 signatures. Consequently, OpenSSL may incorrectly verify X.509 and other certificates, leading to a bypass of trust and authentication mechanisms.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet
Debian
CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
vendor_debian·2006·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla...
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.7-1)
Debian
CVE-2006-4339: openssl - OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using a...
vendor_debian·2006·CVSS 4.3
CVE-2006-4339 [MEDIUM] CVE-2006-4339: openssl - OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using a...
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
Scope: local
bookworm: resolved (fixed in 0.9.8b-3)
bullseye: resolved (fixed in 0.9.8b-3)
forky: resolved (fixed in 0.9.8b-3)
sid: resolved (fixed in 0.9.8b-3)
trixie: resolved (fixed in 0.9.8b-3)
GHSA
GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
ghsa_unreviewed·2022-05-03·CVSS 4.3
CVE-2006-4340 [MEDIUM] CWE-20 GHSA-q7vf-rjwh-chxv: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
GHSA
GHSA-cw9v-mmf8-gmmr: OpenSSL before 0
ghsa_unreviewed·2022-05-03
CVE-2006-4339 [MEDIUM] GHSA-cw9v-mmf8-gmmr: OpenSSL before 0
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
GHSA
GHSA-fjc3-r8f9-57p5: verify
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2006-4790 [MEDIUM] GHSA-fjc3-r8f9-57p5: verify
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
GHSA
GHSA-vv86-x932-f9fc: The libike library, as used by in
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2006-7140 [MEDIUM] GHSA-vv86-x932-f9fc: The libike library, as used by in
The libike library, as used by in.iked, elfsign, and kcfd in Sun Solaris 9 and 10, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents libike from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.
GHSA
GHSA-f6g8-8p5j-hphv: SSH Tectia Client/Server/Connector 5
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2006-5484 [MEDIUM] GHSA-f6g8-8p5j-hphv: SSH Tectia Client/Server/Connector 5
SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.
OSV
CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
osv·2006-09-15·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340: Mozilla Network Security Service (NSS) library before 3
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
OSV
CVE-2006-4339: OpenSSL before 0
osv·2006-09-05·CVSS 4.3
CVE-2006-4339 [MEDIUM] CVE-2006-4339: OpenSSL before 0
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-4340 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-4340 [MEDIUM] CVE-2006-4340 security flaw
CVE-2006-4340 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates, a similar vulnerability to CVE-2006-4339. NOTE: on 20061107, Mozilla released an advisory stating that these versions were not completely patched by MFSA2006-60. The newer fixes for 1.5.0.7 are covered by CVE-2006-5462.
Bugzilla
CVE-2006-4790 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2006-4790 [MEDIUM] CVE-2006-4790 security flaw
CVE-2006-4790 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2006-4339 openssl signature forgery
bugzilla·2008-01-29·CVSS 4.3
CVE-2006-4339 [MEDIUM] CVE-2006-4339 openssl signature forgery
CVE-2006-4339 openssl signature forgery
Common Vulnerabilities and Exposures assigned an identifier CVE-2006-4339 to the following vulnerability:
OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8 before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents OpenSSL from correctly verifying X.509 and other certificates that use PKCS #1.
References:
http://www.securityfocus.com/archive/1/archive/1/445231/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/445822/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/456546/100/200/threaded
http://www.imc.org/ietf-openpgp/mail-archive/msg14307.html
http://marc.theaimsg
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-09·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.5.0 SR3:
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For example, an applet may grant
itself permissions to read and write lo
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.3.1 SR10a. A
security update is required.
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For example, an applet may grant
itself permissions to read and write local files or execute
local applications that are accessible to the user running the
untrusted applet. (sun#102729) CVE-2006-6731
public=20060104,impact=critical
An RSA(1
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
+++ This bug was initially created as a clone of Bug #226981 +++
IBM fixed a number of flaws in their Java Runtime Environment in 1.4.2 SR7. A
security update is required for java-ibm-1.4.2 for RHEL3 Extras
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may indepen
Bugzilla
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
bugzilla·2007-02-02·CVSS 4.3
CVE-2006-6736 [MEDIUM] CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
CVE-2006-6736 Multiple JRE flaws (CVE-2006-6737 CVE-2006-6745 CVE-2006-6731 CVE-2006-4339)
IBM fixed a number of flaws in their Java Runtime Environment in 1.4.2 SR7. A
security update is required for java-ibm-1.4.2 for RHEL4 Extras
http://www-128.ibm.com/developerworks/java/jdk/alerts/
Two vulnerabilities in the Java Runtime Environment may
independently allow an untrusted applet to access data in other
applets. CVE-2006-6736 CVE-2006-6737 (sun#102732)
Two vulnerabilities in the Java(TM) Runtime Environment with
serialization may independently allow an untrusted applet or
application to elevate its privileges. (sun#102731) CVE-2006-6745
Two buffer overflow vulnerabilities in the Java(TM) Runtime
Environment may independently allow an untrusted applet to
elevate its privileges. For ex
Bugzilla
CVE-2006-3738 OpenSSL issues (CVE-2006-4343, CVE-2006-2940, CVE-2006-2937, CVE-2006-4339)
bugzilla·2006-10-03·CVSS 7.8
CVE-2006-3738 [HIGH] CVE-2006-3738 OpenSSL issues (CVE-2006-4343, CVE-2006-2940, CVE-2006-2937, CVE-2006-4339)
CVE-2006-3738 OpenSSL issues (CVE-2006-4343, CVE-2006-2940, CVE-2006-2937, CVE-2006-4339)
+++ This bug was initially created as a clone of Bug #206940, Bug #207274,
and Bug #207276 +++
Four CVE issues:
-- Two from Bug #206940
1) Buffer Overflow: Tavis Ormandy and Will Drewry of the Google Security
Team discovered a buffer overflow in SSL_get_shared_ciphers utility
function, used by some applications such as exim and mysql. An attacker
could send a list of ciphers that would overrun a buffer. CVE-2006-3738
2) Denial of Service: Tavis Ormandy and Will Drewry of the Google Security
Team discovered a possible DoS in the sslv2 client code. Where a client
application uses OpenSSL to make a SSLv2 connection to a malicious server
that server could cause the client to crash. CVE-2006-4343
-- O
Bugzilla
CVE-2006-4339 RSA signature forgery
bugzilla·2006-09-05·CVSS 4.3
CVE-2006-4339 [MEDIUM] CVE-2006-4339 RSA signature forgery
CVE-2006-4339 RSA signature forgery
Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5
signatures. Where an RSA key with exponent 3 is used it may be possible
for an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly
verified by implementations that do not check for excess data in the RSA
exponentiation result of the signature.
The Google Security Team discovered that OpenSSL is vulnerable to this
attack. This issue affects applications that use OpenSSL to verify X.509
certificates as well as other uses of PKCS #1 v1.5. (CVE-2006-4339)
http://www.openssl.org/news/secadv_20060905.txt
Also affects RHEL3, RHEL2.1, and the OpenSSL compatibility packages in those
releases.
Discussion:
An advisory has been issued which should help the problem
described in
Bugzilla
CVE-2006-4339 RSA signature forgery
bugzilla·2006-09-05·CVSS 4.3
CVE-2006-4339 [MEDIUM] CVE-2006-4339 RSA signature forgery
CVE-2006-4339 RSA signature forgery
+++ This bug was initially created as a clone of Bug #205180 +++
Daniel Bleichenbacher recently described an attack on PKCS #1 v1.5
signatures. Where an RSA key with exponent 3 is used it may be possible
for an attacker to forge a PKCS #1 v1.5 signature that would be incorrectly
verified by implementations that do not check for excess data in the RSA
exponentiation result of the signature.
The Google Security Team discovered that OpenSSL is vulnerable to this
attack. This issue affects applications that use OpenSSL to verify X.509
certificates as well as other uses of PKCS #1 v1.5. (CVE-2006-4339)
http://www.openssl.org/news/secadv_20060905.txt
Discussion:
Errata support for SH4 cross-platform ented.
ftp://patches.sgi.com/support/free/security/advisories/20060901-01-P.aschttp://dev2dev.bea.com/pub/advisory/238http://docs.info.apple.com/article.html?artnum=304829http://docs.info.apple.com/article.html?artnum=307177http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01070495http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01118771http://itrc.hp.com/service/cki/docDisplay.do?docId=c00849540http://jvn.jp/en/jp/JVN51615542/index.htmlhttp://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-000079.htmlhttp://lists.apple.com/archives/Security-announce/2007/Dec/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2006/Nov/msg00001.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000008.htmlhttp://marc.info/?l=bind-announce&m=116253119512445&w=2http://marc.info/?l=bugtraq&m=130497311408250&w=2http://openvpn.net/changelog.htmlhttp://secunia.com/advisories/21709http://secunia.com/advisories/21767http://secunia.com/advisories/21776http://secunia.com/advisories/21778http://secunia.com/advisories/21785http://secunia.com/advisories/21791http://secunia.com/advisories/21812http://secunia.com/advisories/21823http://secunia.com/advisories/21846http://secunia.com/advisories/21852http://secunia.com/advisories/21870http://secunia.com/advisories/21873http://secunia.com/advisories/21906http://secunia.com/advisories/21927http://secunia.com/advisories/21930http://secunia.com/advisories/21982http://secunia.com/advisories/22036http://secunia.com/advisories/22044http://secunia.com/advisories/22066http://secunia.com/advisories/22161http://secunia.com/advisories/22226http://secunia.com/advisories/22232http://secunia.com/advisories/22259http://secunia.com/advisories/22260http://secunia.com/advisories/22284http://secunia.com/advisories/22325http://secunia.com/advisories/22446http://secunia.com/advisories/22509http://secunia.com/advisories/22513http://secunia.com/advisories/22523http://secunia.com/advisories/22545http://secunia.com/advisories/22585http://secunia.com/advisories/22671http://secunia.com/advisories/22689http://secunia.com/advisories/22711http://secunia.com/advisories/22733http://secunia.com/advisories/22758http://secunia.com/advisories/22799http://secunia.com/advisories/22932http://secunia.com/advisories/22934http://secunia.com/advisories/22936http://secunia.com/advisories/22937http://secunia.com/advisories/22938http://secunia.com/advisories/22939http://secunia.com/advisories/22940http://secunia.com/advisories/22948http://secunia.com/advisories/22949http://secunia.com/advisories/23155http://secunia.com/advisories/23455http://secunia.com/advisories/23680http://secunia.com/advisories/23794http://secunia.com/advisories/23841http://secunia.com/advisories/23915http://secunia.com/advisories/24099http://secunia.com/advisories/24930http://secunia.com/advisories/24950http://secunia.com/advisories/25284http://secunia.com/advisories/25399http://secunia.com/advisories/25649http://secunia.com/advisories/26329http://secunia.com/advisories/26893http://secunia.com/advisories/28115http://secunia.com/advisories/31492http://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://security.freebsd.org/advisories/FreeBSD-SA-06:19.openssl.aschttp://security.gentoo.org/glsa/glsa-200609-05.xmlhttp://security.gentoo.org/glsa/glsa-200609-18.xmlhttp://securitytracker.com/id?1016791http://securitytracker.com/id?1017522http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.566955http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.605306http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102656-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102657-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102686-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102696-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102722-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102744-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102759-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-200708-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201247-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201534-1
+ 300 more references
2006-09-05
Published